City
Epaper

Apple finds 'no evidence' that Mail bug used to exploit iPhone, iPad users

By IANS | Updated: April 24, 2020 16:20 IST

Apple has found 'no evidence in report by cybersecurity company ZecOps that discovered two vulnerabilities in Apple iOS mail which they believed are widely exploited in the wild to target iPhone and iPad users.

Open in App

San Francisco, April 24 Apple has found 'no evidence in report by cybersecurity company ZecOps that discovered two vulnerabilities in Apple iOS mail which they believed are widely exploited in the wild to target iPhone and iPad users.

The security researchers at San Francisco-based ZecOps discovered the bugs in the default iOS and iPadOS Mail app. The bugs allow to run remote code in the context of MobileMail (iOS 12) or maild (iOS 13). Successful exploitation of this vulnerability would allow the attacker to leak, modify, and delete emails.

"Apple takes all reports of security threats seriously. We have thoroughly investigated the researcher's report and, based on the information provided, have concluded these issues do not pose an immediate risk to our users," the tech giant said in a statement on Thursday.

The company added that the researcher identified three issues in Mail, "but alone they are insufficient to bypass iPhone and iPad security protections, and we have found no evidence they were used against customers".

ZecOps had said that "additional kernel vulnerability would provide full device access we suspect that these attackers had another vulnerability. It is currently under investigation".

What is more, on iOS 13, end users do not require to perform any action for the exploitation to succeed. On iOS 12, the bug requires the victim to click on an email.

If an attacker controls the mail server, the attack can be performed without any clicks on iOS 12 too, the researchers said.

iOS is vulnerable to these bugs at least since iOS 6 –September 2012, ZecOps said, adding that it did not check earlier versions. MacOS is not vulnerable to these bugs, it added.

Apple said that these potential issues will be addressed in a software update soon.

"We value our collaboration with security researchers to help keep our users safe and will be crediting the researcher for their assistance," the company said.

( With inputs from IANS )

Tags: ZecOps, Inc.appleSupport companyApple education
Open in App

Related Stories

TechnologyIT Layoffs 2025: Microsoft, Google, Apple Among 284 Tech Companies That Cut Jobs in First 5 Months

International"Don’t Set Up Production in India, Make In U.S": Donald Trump Sends Out Clear Message To Apple CEO Tim Cook

Health5 Foods to Add to Your Plate to Stay Super Healthy

TechnologyApple Bans 135,000 Apps From App Store Over Missing Trader Information

TechnologyiOS 18.2: Apple Rolls Out 10 New Features in Latest Software Update

Technology Realted Stories

TechnologyPanchayati Raj Ministry to join Bhashini to boost e-governance at grassroot level

TechnologyTinder Makes Dating Social with Double Date Feature for You and Your Bestie

TechnologyCentre launches Rs 3,000 FASTag annual pass for cars to ease highway drive

TechnologyCrisil suggests excluding gold from India’s core inflation index for clear domestic trends

TechnologyIndian defence entities projected to see revenue expansion of 15-17 pc in FY26: Report